Privacy Policy
Last updated: 29 July 2026.
1. Who we are
SmartResume ("we", "us", "our") operates www.smartresumeltd.com and its related web, mobile, and browser-extension applications. We are the data controller for the personal data described in this policy. This policy explains what personal data we collect, why we collect it, the legal bases we rely on, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Controller: Smart Resume Ltd, a company registered in England and Wales (company number 16403054), with its registered office at 86 Mornington Crescent, Hounslow, London, TW5 9SS. We are established in the United Kingdom. Our ICO registration reference is ZB985408.
2. Data we collect
We process the following categories of personal data:
- Account data: name, email address, password hash, and authentication-provider identifiers.
- Resume and career content: work history, education, skills, and other content you author or upload.
- Application activity: jobs viewed, saved, and applied to; application status and outcomes.
- Communications: messages exchanged with recruiters, support requests, and notification preferences.
- Interview-practice data: mock-interview responses and, only if you explicitly enable it, video recordings.
- Usage and device data: log data, IP address, browser/device metadata, and privacy-preserving analytics events.
- Payment data: your subscription tier and billing status. Payment-card details are handled by our payment provider and are never stored by us directly.
3. How we use AI
SmartResume uses generative-AI models to power features such as resume-writing assistance, scoring, chat, translation, and job matching. Every generative-AI call is routed through a single internal AI Gateway. No part of our applications ever calls an AI provider directly. The gateway:
- redacts personally identifying information from prompts before any prompt leaves the platform for a provider;
- uses a tiered set of AI providers (a primary provider with automatic failover to secondary providers) rather than sending your data from your device to a provider;
- meters the cost of AI usage per user and per feature, and caps free-tier AI usage accordingly.
By default we do not use your content to train AI models. You control this through the "Keep my data out of AI model training" setting, which is on by default (see section 4). We do not sell your personal data. If you use AI-assisted interview help (mock-interview practice or the Live Interview Copilot), your use of those tools is candidate-only data and is never shared with recruiters (see section 5).
4. Consent and how to change it
When you create an account you must agree to the processing of your personal data and accept our Terms of Service. Beyond those, we offer a set of optional consents that are off by default (except AI-training opt-out, which is on by default to protect you). You can review and change any of these at any time from Settings → Privacy → Consents. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
The optional consent categories are:
- Product updates and promotions (marketing) — off by default. Promotional contact only if you opt in.
- Keep my data out of AI model training — on by default. We do not use your data to train AI models unless you turn this off. This is an opt-out control: leaving it on is the protective state.
- Video recording — off by default. Lets us record video during mock interviews. Recordings auto-delete after 30 days, and each session asks again.
- Location data — off by default. Improves local job matches and commute estimates.
- Sharing with job boards — off by default. Lets us pass your profile to partner job boards when you apply through them.
- Third-party integrations — off by default. Enables optional integrations with third-party services you connect.
- Social sharing of achievements — off by default. Lets you share achievement highlights outside SmartResume. This is separate from third-party integrations; granting one does not grant the other.
5. Interview practice and Live Copilot privacy
Self-practice mock-interview data and Live Interview Copilot suggestions are candidate-only. They are never shared with recruiters, and this is enforced at the database and API layer, not only in the interface. Live Copilot never records video and never posts or speaks on your behalf. Where you have enabled video recording for mock interviews, those recordings automatically delete after 30 days.
We do not analyse your face, your voiceprint, or your emotions. Interview practice feedback is based only on the text of your answer (what you typed or what your spoken answer transcribes to) and objective, non-biometric delivery measures such as words per minute, pauses, and answer length. We perform no face-geometry, voiceprint, facial-landmark, or expression or emotion analysis, and no third-party service on this path does either.
6. Email inbox tracking
Email inbox tracking works by forwarding, not by connecting to your mailbox. When you enable it, we give you a unique SmartResume forwarding address; you forward job-related emails to it, or set a one-time auto-forward filter with your email provider. We do not access, read, or connect to your email account, and we request no email-provider permissions. It works with any email provider.
We parse the emails you forward server-side to derive status events (for example, that an interview-invitation email was detected), then discard the message. We never store the raw content of forwarded emails — only the derived status event. Classifying a forwarded email may use our AI Gateway (the same PII-redacted, tiered-provider system described in section 3 above).
7. Saving jobs from other sites
Our job-capture feature acts only on a single job you choose to save, one item at a time and always at your initiative. We do not bulk-crawl, enumerate, or scrape third-party sites, and we do not fetch content from login-walled pages. Content captured from third-party sites is sanitised before any AI processing.
8. Analytics and cookies
Our web analytics, when enabled, is a self-hosted, cookieless tool (Umami) that sets no cookies, collects no personally identifying information in its events, and does not track you across other websites. We do not use third-party advertising or cross-site tracking. We do not currently set cookies at all: your sign-in state is held in your browser's local storage on your device, not in a cookie. If we introduce strictly necessary cookies in the future, we will update this policy first.
9. Data retention and deletion
We keep personal data only as long as necessary for the purposes described in this policy, or as required by law. User-generated content (resumes, applications, and similar records) is soft-deleted rather than immediately erased: when you delete such content it is retained recoverably for a limited window before permanent removal, so you can restore it from Trash. Mock-interview video recordings auto-delete after 30 days. When you close your account we delete or anonymise your personal data, subject to any legal retention obligations.
10. International transfers and subprocessors
To provide the service we use a small number of third-party processors ("subprocessors"). Some are located outside the United Kingdom; where personal data is transferred internationally we rely on appropriate safeguards such as the UK International Data Transfer Agreement or adequacy regulations. Our subprocessors are:
- AI providers — accessed only through our internal AI Gateway, with PII redacted before any prompt is sent. These include Anthropic (Claude) as our primary provider, and may include OpenAI and Google as automatic failover providers, only where that tier is enabled.
- Neon — managed PostgreSQL database hosting.
- Hostinger — virtual private server hosting for our backend services.
- Vercel — hosting for our web front end.
- Stripe — processing of subscription payments. Billing is handled by Stripe, a PCI-DSS-compliant payment processor, and we never store your card details (paid billing integration forthcoming).
- Mailgun (EU region) — inbound email parsing for the forwarding-based application tracking feature described in section 6; receives forwarded mail transiently and passes it to our webhook; raw content is discarded after a status event is derived.
We keep this list current and will update it as our processors change.
11. Your rights (UK GDPR)
Subject to applicable law, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Where we rely on consent, you may withdraw it at any time. To exercise any of these rights, contact us using the details in section 12. If you are unsatisfied with our response, you may complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk.
12. Contact us
For any privacy question or to exercise your rights, contact our data-protection contact: Amer Rauf, Founder. Email: privacy@smartresumeltd.com. Post: Smart Resume Ltd, 86 Mornington Crescent, Hounslow, London, TW5 9SS.